Starship
starship / search / error-tracking-with-catchjs

Audit report

Error Tracking with CatchJS

Broad accessReach : broad

by Simple Integrations · Reporting · Shopify App Store

Reporting
Risk level
Broad access
Executive summary

Know when your store is breaking

Key insights

  • App launched September 2018, listing last reviewed August 22, 2021, long maintenance silence.
  • Only 1 review at 4.0 stars, indicating very low adoption.
  • Privacy policy exists but omits residency, sub-processors, retention, and certifications.
  • Publisher domain catchjs.com responds 200/HTTPS but does not advertise HSTS or CSP.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Know when your store is breaking

Key insights
  • App launched September 2018, listing last reviewed August 22, 2021, long maintenance silence.
  • Only 1 review at 4.0 stars, indicating very low adoption.
  • Privacy policy exists but omits residency, sub-processors, retention, and certifications.
  • Publisher domain catchjs.com responds 200/HTTPS but does not advertise HSTS or CSP.
  • No public CVE, breach, or security incident tied to CatchJS or Simple Integrations.
  • App category (frontend JS error tracking) implies a storefront script tag, supply-chain risk vector inherent to the model.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_script_tags
Medium

L'app injecte un script de suivi des erreurs sur la vitrine, ce qui nécessite la création de balises de script, induit de la fonction déclarée de l'app.

read_script_tags
Low

L'app doit lire les balises de script existantes pour gérer son installation, induit de la fonction déclarée de l'app.

read_themes
Low

La détection d'erreurs de code sur la vitrine peut requérir la lecture des fichiers de thème, induit de la fonction déclarée de l'app.

read_reports
Low

L'app relève de la catégorie Reporting et présente des rapports d'erreurs, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
catchjs.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS reachable with HTTP/2 200; X-Frame-Options: sameorigin present; no HSTS or CSP advertised in response headers.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not assert GDPR, CCPA, SOC2, ISO27001, PCI DSS, or HIPAA compliance, nor publish a data retention period or sub-processor list.

Privacy policy
Track record

Publisher reputation

Publisher
Simple Integrations
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.